How do you use eve-iac?¶
EVE IaC is a desired-state and interaction automation layer for EVE-NG. It combines Git-based Infrastructure as Code, safe reconciliation, and Day-0 console automation through one API. eve-iac is not an official EVE-NG product. Clients talk only to eve-iac-agent over HTTPS. They never call native EVE REST.
Define the infrastructure. Define how to interact with it. Automate both.
You are on eve-iac.io — the public documentation site. Source code and downloadable packages are on GitLab (not this domain).
Git / VS Code / CI / AI → eve-iac-agent (HTTPS :8787) → EVE-NG
| Under the agent | |
|---|---|
| Desired state | Git YAML (topology.yml, configs/). Validate → plan → reconcile. |
| Interaction as Code | Consoles (exec / wait / run) and live link quality / suspend. |
Git is desired truth. EVE/agent is runtime truth. The VSIX Cockpit is a derived view — never a third source of truth. Why EVE IaC? · Architecture
Pick the path that matches how you work.
Operator¶
Use VS Code or Cursor to create, import, edit, and operate EVE-NG labs. You do not need to write code.
DevOps / CI-CD¶
Validate, plan, deploy, and reconcile labs from pipelines with the eve-iac CLI. Console automation supports Day-0 bootstrap before management IP or SSH exist.
Developer¶
Build integrations with the Python, TypeScript, or Go SDK, or call the HTTPS API.
What eve-iac is¶
Git files are desired state (topology.yml, configs/, .eve-iac.yml). The agent/EVE is runtime truth. The VSIX Cockpit is a derived view. Validate, plan, deploy, and reconcile are explicit operations. Importing an existing lab is not the same as pulling later changes with from_eve.
Important principles:
- Persona tools, one API. The VSIX, CLI, and SDKs share
eve-iac/v1. - Infrastructure vs interaction. Topology and startup-configs are desired state (Infrastructure as Code). Consoles, exec, wait, run, and live link quality/suspend are operational (Interaction as Code).
- Desired state vs live state. Topology and startup-configs are desired. Consoles and inspect are operational. The Cockpit is derived, not authoritative.
- Reconcile is fail-closed, then progressive. Any unsupported transition blocks all EVE writes. Independent live-safe changes apply only when the rest of the plan is reachable; remaining
requires_stopwork needs confirmation and a matching plan identity. Partial convergence is that leftover stop work, not “skip the hard rows”. See Architecture and Plan / reconcile. - Destructive work is explicit. Destroy, prune, wipe, replace, and classified stops require confirmation (
--yesplus--plan-identitywhen stop work remains, the IDE prompt, or MCPconfirm=true).--yesdoes not invent a plan identity. - TLS is pinned. Trust the agent certificate in the IDE, or pass
--ca-file/ca_pemin automation. The CLI has no TOFU; optional--insecureis lab/dev only (never CI). - Git-driven, not autonomous GitOps. Git holds desired state. Pipelines push validate → plan → reconcile. There is no pull-based continuous reconciler. See Git-driven workflow.
Install quickly¶
Packages are on this GitLab project’s Package Registry and Releases — not public PyPI, npm, or a Go proxy. Copy the registry form, not the bare package name.
| You | Start here |
|---|---|
| VS Code / Cursor | Install the VSIX (eve-iac-client-0.5.3.vsix) |
| Pipelines | Install the CLI |
| Python | pip install eve-iac --index-url https://gitlab.com/api/v4/projects/eve-ng-dev%2Feve-iac/packages/pypi/simple — install · SDK |
| Node | npm config set @eve-iac:registry https://gitlab.com/api/v4/projects/eve-ng-dev%2Feve-iac/packages/npm/ then npm install @eve-iac/sdk — install · SDK |
| Go | GitLab tarball + replace — install · SDK |
Canonical names stay eve-iac / @eve-iac/sdk / github.com/eve-iac/eve-iac/sdk/go. Agent .deb, VSIX, CLI/Python wheel, npm, and Go tarball are published from this GitLab project (Package Registry + Release on tags), not from public indexes, the Marketplace, or a Debian archive. Local build: make pack-sdk deb vsix.
Project status¶
- License: AGPL-3.0-only
- Package version and API id are different. See versioning.
- Candidate contract
eve-iac/v1is not a published freeze yet. - Compatibility — agent/client pairing, workstations, and what is not claimed.